Evela

Privacy Policy

Last updated: 12 September 2026

Evela is a personal finance app that helps you track your money by hand or by voice. Your data stays yours — we never connect to your bank, and we collect as little as possible. This policy explains what we collect, why, where it lives, and how you stay in control.

Contents

  1. Who we are
  2. What we collect
  3. How we use it
  4. Voice & AI features
  5. Who we share with
  6. Where data is stored
  7. How long we keep it
  8. Your rights & choices
  9. Deleting your account
  10. Security
  11. Children
  12. Changes
  13. Contact

1. Who we are

“Evela” (“we”, “us”, “our”) provides the Evela mobile app and the website at evela.ai. If you have any question about this policy or your data, email us at hello@evela.ai.

Evela is manual-first: you enter your finances yourself, by typing or by voice. We do not link to your bank accounts, cards, or any open-banking service, so we never see your real bank logins, statements, or card numbers.

2. What we collect

Account & identity

You sign in with Google or Apple. We do not run passwords of our own. From your sign-in we receive and store your email address and a provider user ID. (If you use “Sign in with Apple” and choose to hide your email, we only ever see Apple’s private relay address.) Authentication is handled by our infrastructure provider, Supabase.

Financial information you enter

This is the core content of the app, all entered by you:

Balances are calculated on the fly and are not stored as such. We do not receive any of this from third parties — it only exists because you typed or dictated it.

Category corrections. When you pick or correct a transaction’s category, we keep a small memory of it — a normalized version of the merchant/description text paired with the category you chose — so the app stops asking about the same merchant twice. This memory does not include amounts or dates, and it is kept separately from the transaction: deleting or editing that transaction later does not erase it, since the whole point is remembering what you taught the app. It is erased when you delete your account (section 9).

Profile settings

A minimal profile: your base currency, your time zone (so a transaction lands on the right calendar day), and whether you finished onboarding. Preferences such as which currencies you display, your reminder schedule and your analytics choice stay on your device. We do not collect your name, photo, phone number, postal address, or date of birth.

Voice recordings (only if you use voice entry)

When you tap to add an entry by voice, the app sends your speech to our server for transcription — either as a short recorded clip or as a live audio stream while you talk, depending on your connection. Either way, our server forwards it straight to our speech-to-text provider and never writes it to our database or keeps it on our servers — we keep only the text you then confirm. Any temporary copy on your device is deleted as soon as it’s been sent. The speech provider processes the audio only to produce the transcript: we have opted out of its model-improvement programme, so your voice is not kept by it or used to train its models (section 4). Voice entry is optional: if you don’t grant the microphone permission, everything else in the app still works.

Usage analytics

We collect product-usage events — which screens you open, which actions you take, counts, and coarse buckets — to understand how the app is used and improve it. These events never include your amounts, notes, account or category names, or your email, and we never send your Evela account ID to our analytics provider: events carry only a random, device-level identifier generated by the analytics SDK, so we cannot connect them back to your account. As with any internet request, our analytics provider also receives your device’s IP address and derives an approximate (city-level) location from it. We use that in aggregate, and only for one thing: to see which countries and regions Evela is being used in, so we know where to take the product next. It is never used to identify you or to work out where you personally are, and it is never combined with your financial data. Analytics are on by default, and you can turn them off at any time in Settings → Data & privacy → Analytics. Turning the switch off stops both the events we send and the automatic ones the analytics SDK collects. The setting is stored on your device, so if you use Evela on more than one device, turn it off on each.

Diagnostics & crash reports

If the app or our server hits an error, a diagnostic report is sent to our error-monitoring provider so we can fix it. It contains the error type, a stack trace, and technical context about the device and build (model, OS version, app version). Request bodies, headers, query strings and any custom payload are stripped out before sending, so your amounts, notes, account and category names, transcripts and access tokens do not travel with the report, and reports are not tied to your name or email.

Subscription data

If you buy a subscription, the purchase is processed by the app store (Apple or Google) and our subscriptions provider, RevenueCat. So that a purchase follows your account across devices, we tell RevenueCat your Evela user ID (a random identifier) — never your name or email. In return we receive only whether a subscription (entitlement) is active. We never see or store payment card numbers.

On-device security data

A database encryption key, your session tokens, and — if you set one — your app-lock PIN (stored only as a salted, hashed value) are kept in your device’s secure store (iOS Keychain / Android Keystore). These stay on your device and are not sent to us.

3. How we use your data

We do not sell your personal data, and we do not use your financial data for advertising.

4. Voice & AI features

Some features use automated processing to save you time. Because of that, some of your financial information does leave our systems — it is sent to the specialist providers listed in section 5, who act as our sub-processors and return a result to us. Here is exactly what goes where:

Our primary AI provider is Qwen, hosted by DeepInfra. If it fails or is unavailable, the same request is automatically retried once with Anthropic. Which one handled a given request depends only on availability.

We do not store the text you send or the AI’s response, and we never use your data to train a model of our own. Nor do our AI providers train on it: Anthropic deletes the inputs and outputs of API requests within 30 days and does not train on them, and DeepInfra does not retain them (beyond short-lived storage for debugging) or train on them without explicit consent. Only technical usage metadata (provider, model, task type, plan, token counts and cost, linked to your account so we can enforce fair-use quotas) is logged — never the content of your entries.

Your voice is not training data either. Our speech-to-text provider (Deepgram) receives the clip and nothing else — no account ID, no email, no name — and uses it solely to return the transcript. We have opted out of its Model Improvement Program, so the audio is not retained by the provider or used to improve its speech-recognition models, and under our agreement it is never sold, shared onward, or used for advertising. If you would rather your voice were not processed at all, type your entries instead: text you type never reaches the speech provider. Everything you type or record is still yours to delete at any time (section 9).
You’re always in control. The AI only proposes a draft that you review and confirm — nothing is saved automatically. AI-generated text is informational only and is not financial, investment, tax, or legal advice. It may be inaccurate; decisions are yours.

5. Who we share data with

We don’t sell your data and we don’t hand it to anyone for their own purposes. But we can’t honestly say “we never share it”: Evela runs on a small set of service providers (“sub-processors”), and some of them — our speech and AI providers in particular — do receive financial information you entered, because that is the only way those features can work. Each provider receives only what it needs and is bound by its own agreement with us. All of them process what they receive on our instructions, only to return a result to us — none of them uses it for purposes of their own, and section 4 spells this out for our speech and AI providers. Here is the full list:

ProviderPurposeWhat it processes
SupabaseSign-in & cloud databaseYour email & provider ID; all the financial data you enter
PowerSyncSync between your device & the cloudA replica of your synced app data, hosted in its cloud
RailwayHosts our backend serverEverything that passes through our API, in transit
Google & AppleSign-in providersProvide us your email & a user ID
DeepgramSpeech-to-textYour voice clip, and therefore whatever you said in it — processed only to return the transcript; not retained or used to train its models (section 4)
DeepInfra (Qwen)AI parsing, categorization, insight & forecast wordingThe text of your entry; your account & category names; aggregated monthly and forecast figures (see section 4)
AnthropicAutomatic AI fallbackThe same as the row above, when the primary provider fails
PostHogProduct analyticsUsage events under a random device-level ID + your IP address, from which an approximate location is derived (section 2) — no account ID, email, amounts or names
SentryError & crash monitoringError type, stack trace, device/OS/app version — payload fields scrubbed
RevenueCat + app storesSubscriptionsYour Evela user ID and purchase / entitlement status (no card details)

We may also disclose information if required by law, or to protect the rights, safety, or property of our users or Evela.

Currency exchange rates shown in the app come from a public rates service and involve no personal data.

6. Where your data is stored

Your account and financial data are stored in our cloud database (Supabase) in the European Union (Frankfurt, Germany). Our sync service (PowerSync) keeps a replica of that data in its own cloud so your devices stay in step. Our backend server (Railway) runs in the EU (Amsterdam, Netherlands), and error diagnostics (Sentry) are stored in the EU (Germany). Product analytics (PostHog) — including the IP address the approximate location in section 2 is derived from — are processed in the United States. Our AI and speech providers process your entries on their infrastructure, which may be in the United States or other countries.

This means your data may be processed in countries other than the one you live in. Wherever it goes, it is protected by the security measures described in this policy and by our agreements with each provider.

7. How long we keep your data

8. Your rights & choices

Depending on where you live (for example, under the EU/UK GDPR or similar laws), you may also have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. To exercise any of these, email hello@evela.ai and we’ll help. You also have the right to complain to your local data-protection authority.

9. Deleting your account

You can permanently delete your account and data yourself: open Settings → Delete account and data and confirm. This cannot be undone. It removes your sign-in record and, with it, your accounts and account groups, transactions, categories, tags, reconciliation entries, category corrections, insight preferences, profile, entitlement records and AI usage logs from our live database, and clears all Evela data from your device — including the local encrypted database and the keys, tokens and app-lock PIN held in the device secure store. Shared reference data that isn’t personal to you (such as public currency rates) is not affected.

To be straight with you about the edges of that:

No longer have the app installed? You can still delete your account without it: email hello@evela.ai from the address you signed in with (Google or Apple), and we will delete your account and all associated data for you within 30 days and confirm by reply. The same address works if you want us to chase anything beyond the in-app deletion with our providers on your behalf.

10. Security

No system is perfectly secure, but we work to protect your data using industry-standard measures.

11. Children

Evela is not directed to children and is intended for adults. You must be at least 18 years old (or the age of majority where you live) to use Evela. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact hello@evela.ai and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we do, we’ll change the “Last updated” date above, and for significant changes we’ll let you know in the app. Continued use of Evela after an update means you accept the revised policy.

13. Contact us

Questions, requests, or concerns about your privacy? Email hello@evela.ai.